CyberHQ automates the work your security team repeats every day — Patch Tuesday reporting, zero-day intelligence, phishing triage, endpoint and network defence — and feeds every result into one unified command center.
Real, running automations that detect, enrich, report and respond. Every capability below is live in the platform.
Pulls Microsoft MSRC and vendor advisories, reconciles zero-days, and generates a full banded SOC report with CSV export — automatically, every month.
Tracks the CISA KEV catalogue and security press, enriches severity and CVSS from NVD, and posts colour-coded briefings to your channels.
Paste an email and get a verdict — SPF, DKIM and DMARC validation, IOC extraction, reputation enrichment, and a written analyst summary.
The deepest module in the platform. Connect a mailbox to scan, score, quarantine, soft-delete and restore messages, with a full audit log.
Look up IPs, domains, URLs and file hashes against multiple live intelligence sources at once, and get a single scored verdict.
Probe your own web properties for injection, exposure and misconfiguration classes, with findings ranked by impact and remediation guidance.
Live host telemetry, process and service inspection, network discovery, and session monitoring across the estate.
Detect sensitive data exposure and policy violations before it leaves the perimeter, with severity scoring and alerting.
Adversary simulation and defensive validation side by side — test detection coverage and prove your controls actually fire.
Every module runs in parallel and reports into the same unified dashboard.
Central operations view with live incident state and analyst queue.
Ask about any IP, hash, user or alert and get triage with recommended actions.
Build and run response playbooks on a live canvas.
Mailbox scanning, phishing verdicts, quarantine and restore.
Host telemetry, processes, services, startup and removable media.
Discovery, traffic visibility and exposure checks.
Sensitive-data detection and policy enforcement.
Assess and harden the AI systems in your own stack.
IOC lookup, reputation scoring and breach exposure checks.
Attack emulation to validate detection coverage.
Defensive validation and control verification.
Structured export and log summarisation for downstream tooling.
Sentrix is the automation engine inside CyberHQ. Describe an incident-response process in plain English and it designs the workflow — trigger, enrichment, AI decision, condition, action, notification — ready to review and run.
No complex setup. Connect your sources and let the automations run.
Link your mailbox, threat feeds and endpoints. Add intelligence API keys once and every module uses them.
Patch Tuesday reporting, the zero-day feed, or phishing triage — or design your own in Sentrix.
Set the cadence and send results where your team already works — hands-off from there.
Audit-ready reports and prioritised findings land in your unified dashboard.
Every plan includes the core engine and 24/7 monitoring. Self-serve checkout is coming soon — get in touch and we will set your account up directly.
For individuals getting started.
For growing security teams.
For large organizations.
Sentrix is the security automation engine inside CyberHQ. You describe an incident-response process in plain English and Sentrix designs the workflow — trigger, enrichment, AI decision, condition, action and notification — which you can review on a live canvas. Sentrix is available on Pro and Enterprise plans.
Enrichment draws on VirusTotal, AbuseIPDB, GreyNoise, Shodan, URLScan and Have I Been Pwned for indicators and breach exposure, plus the CISA KEV catalogue, Microsoft MSRC advisories and the NVD for vulnerability intelligence. You supply your own API keys, so lookups run under your own quotas.
No. CyberHQ runs as a hosted command center and connects to the sources you authorise. Endpoint and network telemetry is collected from the host it runs on, and intelligence enrichment is API-based.
API keys are held as environment configuration and are never rendered back to the browser. Sessions are signed server-side and every module enforces authentication. Access to the platform requires an account — nothing is publicly reachable.
Yes. Reports and findings can be exported in structured formats, and log summarisation is built in so results can be forwarded to downstream tooling.
A full banded report reconciling Microsoft MSRC advisories with vendor and press sources, highlighting zero-days and exploited vulnerabilities, with CSV export and scheduled email delivery.
Automate the reporting, intelligence and triage your team repeats every day.